CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100673

HIGHCVSS 8.2NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100673 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100673

HIGHCVSS 8.2NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]